用多智能体框架让安全警报解释更可操作、有证据支持。
(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations

- 构建多智能体系统,基于假设开展结构化调查
- 生成可操作的解释,提升事件分类准确率
- 适合中小型企业安全团队快速理解威胁上下文
安全运营中心依赖异常检测系统标记可疑事件。现有特征级解释对实际调查帮助有限。为有效处理告警,分析师需要了解实体间的上下文关系和可行动的理解。本文提出 (EC)2,一种面向中小型企业网络的事件中心、检测器无关的安全告警解释方法。该方法通过多智能体框架执行结构化、假设驱动的调查,提供基于可验证证据的解释。评估结果表明,该框架能显著提升检测后的分析效率,并生成具有实际操作意义的解释,同时改善事件分类准确率。
原文摘要 · Abstract (English)
Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations grounded in verifiable evidence. Evaluation results show that the proposed framework improves post-detection analysis by generating operationally meaningful explanations, which also enhance event classification accuracy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。